<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Internal LAN Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427846#M557465</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you show "sh ver" from your pix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 04 Jun 2005 21:19:41 GMT</pubDate>
    <dc:creator>a.alekseev</dc:creator>
    <dc:date>2005-06-04T21:19:41Z</dc:date>
    <item>
      <title>PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427843#M557460</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;It seems that I'll show up from time to time with a new problem in my PIX...&lt;/P&gt;&lt;P&gt;My PIX firewall is 506E with IOS Version 6.3(3). It's working for a year with No problem but now a days I noticed a new problem happened for some IPs in the internal Network which protected by my PIX...&lt;/P&gt;&lt;P&gt;The problem is: when I assign internal IP to internal machine it works for minutes and stop working at all... when I changed this IP and assign another IP to the same machine it works fine and so on....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this problem started increase dramatically and I do know now how to solve as it's impossible to assign one of our technical engineer to follow up only with the IP problems issued because of my PIX...&lt;/P&gt;&lt;P&gt;Please, if someone faced such problem and find out how to solve it... I'll be grateful for his help to resolve this problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Magdy Hossein&lt;/P&gt;&lt;P&gt;MAS Technology&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427843#M557460</guid>
      <dc:creator>m.hossein</dc:creator>
      <dc:date>2020-02-21T08:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427844#M557462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say "it works for minutes and stop working at all", does the machine still work on the local LAN at this time?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it only stop working when trying to go through the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What static,nat, and global statements are configured in the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jun 2005 17:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427844#M557462</guid>
      <dc:creator>mlowery</dc:creator>
      <dc:date>2005-06-04T17:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427845#M557464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;yes the machine still working on the LAN at that time...&lt;/P&gt;&lt;P&gt;Yes it only stop working when trying to go through the firewall...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below the part of our configuration you asked for:&lt;/P&gt;&lt;P&gt;----------------------------------------------------&lt;/P&gt;&lt;P&gt;ip address outside 217.52.62.194 255.255.255.192    &lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.250 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 217.52.62.195-217.52.62.214 netmask 255.255.255.192&lt;/P&gt;&lt;P&gt;global (outside) 1 217.52.62.215 netmask 255.255.255.192&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;conduit permit icmp any any&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 217.52.62.193 1&lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will help to resolve the problem....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Magdy Hossein&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jun 2005 19:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427845#M557464</guid>
      <dc:creator>m.hossein</dc:creator>
      <dc:date>2005-06-04T19:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427846#M557465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you show "sh ver" from your pix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jun 2005 21:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427846#M557465</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-06-04T21:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427847#M557466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, all of that looks fine. Now I have several more questions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Is the PIX ip 192.168.1.250 the default gateway of the machine?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the workstation ping 217.525.62.193 when this happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What shows up in your debugging syslog output when the workstaiton tries to connect to an outside IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you looked at the "show xlate" and "show conn" output?  Do you see the workstation's IP in the output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jun 2005 21:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427847#M557466</guid>
      <dc:creator>mlowery</dc:creator>
      <dc:date>2005-06-04T21:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427848#M557467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below the answers for your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- the Output of Show Ver command?&lt;/P&gt;&lt;P&gt;danabeach# show ver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco PIX Firewall Version 6.3(3)&lt;/P&gt;&lt;P&gt;Cisco PIX Device Manager Version 3.0(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Wed 13-Aug-03 13:55 by morlee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;danabeach up 22 hours 22 mins&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:   PIX-506E, 32 MB RAM, CPU Pentium II 300 MHz&lt;/P&gt;&lt;P&gt;Flash E28F640J3 @ 0x300, 8MB&lt;/P&gt;&lt;P&gt;BIOS Flash AM29F400B @ 0xfffd8000, 32KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0: ethernet0: address is 0011.208a.4ea6, irq 10&lt;/P&gt;&lt;P&gt;1: ethernet1: address is 0011.208a.4ea7, irq 11&lt;/P&gt;&lt;P&gt;Licensed Features:&lt;/P&gt;&lt;P&gt;Failover:                    Disabled&lt;/P&gt;&lt;P&gt;VPN-DES:                     Enabled&lt;/P&gt;&lt;P&gt;VPN-3DES-AES:                Enabled&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces: 2&lt;/P&gt;&lt;P&gt;Maximum Interfaces:          2&lt;/P&gt;&lt;P&gt;Cut-through Proxy:           Enabled&lt;/P&gt;&lt;P&gt;Guards:                      Enabled&lt;/P&gt;&lt;P&gt;URL-filtering:               Enabled&lt;/P&gt;&lt;P&gt;Inside Hosts:                Unlimited&lt;/P&gt;&lt;P&gt;Throughput:                  Unlimited&lt;/P&gt;&lt;P&gt;IKE peers:                   Unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- Is the PIX ip 192.168.1.250 the default gateway of the machine? &lt;/P&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- Can the workstation ping 217.525.62.193 when this happens? &lt;/P&gt;&lt;P&gt;NO.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4- Have you looked at the "show xlate" and "show conn" output? Do you see the workstation's IP in the output? &lt;/P&gt;&lt;P&gt;Check the output of Show xlate then Show conn:&lt;/P&gt;&lt;P&gt;danabeach# show xlate&lt;/P&gt;&lt;P&gt;4 in use, 4 most used&lt;/P&gt;&lt;P&gt;Global 217.52.62.195 Local 192.168.1.66&lt;/P&gt;&lt;P&gt;Global 217.52.62.197 Local 192.168.1.65&lt;/P&gt;&lt;P&gt;Global 217.52.62.198 Local 192.168.1.76&lt;/P&gt;&lt;P&gt;Global 217.52.32.196 Local 192.168.1.41&lt;/P&gt;&lt;P&gt;danabeach# show conn&lt;/P&gt;&lt;P&gt;1 in use, 10 most used&lt;/P&gt;&lt;P&gt;UDP out 62.140.73.1:53 in 192.168.1.76:1160 idle 0:01:00 flags -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Local Machine's IP is: 192.168.1.76&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hoep this help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Magdy Hossein&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jun 2005 13:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427848#M557467</guid>
      <dc:creator>m.hossein</dc:creator>
      <dc:date>2005-06-05T13:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Internal LAN Issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427849#M557469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about the syslog?  Does the PIX show any traffic being blocked to or from the 192.168.1.76 address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a "show arp", does the MAC address match the PC's MAC address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jun 2005 17:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-internal-lan-issue/m-p/427849#M557469</guid>
      <dc:creator>mlowery</dc:creator>
      <dc:date>2005-06-05T17:15:01Z</dc:date>
    </item>
  </channel>
</rss>

